Skip to content

Require a recent password for TOTP login - #320

Open
kaareal wants to merge 2 commits into
masterfrom
security/totp-recent-password
Open

kaareal wants to merge 2 commits into
masterfrom
security/totp-recent-password

Conversation

@kaareal

@kaareal kaareal commented Sep 24, 2026 •

Copy link
Copy Markdown
Collaborator

Split from #302.

Problem

POST /1/auth/totp/login issued a full session from just an email and a 6-digit TOTP code. No password was needed.

verifyTotp checked for a recent password only if (authenticator.isMfa), and enableTotp never sets isMfa. The check never ran, so the authenticator app replaced the password instead of acting as a second factor.

Fix

verifyTotp now always calls verifyRecentPassword. The password must have been verified in the last 5 minutes (MFA_THRESHOLD), which the /auth/password/login step does before it asks for the TOTP code.

Behaviour change

  • A TOTP login fails (401) unless it comes within 5 minutes of a password login.
  • An account with no password can no longer log in with TOTP.

Tests

  • New: a TOTP login 10 minutes after the password was last verified returns 401.
  • Existing tests now create users with a password. The lastUsedAt assertion looks up the TOTP authenticator by type, because the user now has both a password and a TOTP authenticator.

@github-actions

Copy link
Copy Markdown

API Changes

No changes.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant